LISTING OF CLAIMS : 

1 . (Previously Presented) A method for monitoring events generated on at least one 
computer system, said method comprising the steps of: 

(a) monitoring a set of event data generated on said at least one system; 

(b) recording said set of event data in a database; 

(c) interrogating said database to thereby select alert event data from said set of event 

data according to a predefined set of rules; 

(d) reading said alert event data and issuing an appropriate action due to said 

generated event, said action issued according to said predefined set of rules; 
and 

(e) determining said action response based upon said pre-defined set of rules and 

based upon a v^eighting factor applied to recorded historical outcomes for 
monitored events. 

2. (Original) A method as claimed in claim 1, wherein said action response occurs in 
real-time as a user interacts with said computer system. 

3. (Previously Presented) A method as claimed in claim 2, wherein said method 
fiarther comprises the step of: (f) issuing said action response to said at least one computer 
system to prevent further interaction of said user with said computer system, 

4. (Cancelled) 

5. (Original) A method as claimed in claim 1, wherein said set of event data is 
monitored from the interaction of one or more users interaction with one or more computers 
on a network. 

6. (Original) A method as claimed in claim 5. wherein said monitored set of event 
data is monitored from a number of sources on said computer network, including any one or 
more of the following network components: the application program layer; the transport 
layer; security layer; operating system. 

7. (Original) A method as claimed in claim 6, wherein said application program layer 
includes any one or more the following: customer relationship management, enterprise 
resource planning; customer billing. 

8. (Original) A method as claimed in claim 6, wherein said operating system includes 
any one or more but not limited to the following: database application server; LAN; router; 
PABX; telephone network; network server. 
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9. (Original) A method as claimed in claim 6, wherein said security layer includes any 
one or more but not limited to the following: firewalls; card-swipe facility access; close- 
circuit security television. 

10. (Original) A method as claimed in claim 1. wherein said method further includes 
the step of: (g) permitting an authorised user to interactively define said set of rules in step 
(c). 

1 1. (Original) A method as claimed in claim 10, wherein said authorised user can 
interactively define and/or amend said set of rules in step (c) using a user graphical interface. 

12. (Original) A method as claimed in claim 11, wherein said graphical interface is a 
web browser. 

13. (Cancelled) 

14. (Original) A method as claimed in claim 1, wherein one or more agent programs 
are provided on at least one computer of said computer system to thereby monitor said set of 
event data. 

15. (Original) A method as claimed in claim 1, wherein said event data is recorded in 
a relational database. 

16. (Original) A method as claimed in claim 15, wherein said event data is assigned a 
unique log identifier in said database to identify the record of each event. 

17. (Original) A method as claimed in claim 16, wherein said unique log identifier is 
used to correlated as a single event, a multiplicity of events generated on one or more 
computer systems. 

18. (Original) A method as claimed in claim 1, wherein a report is generated to report 
said recorded said set of event data. 

19. (Original) A method as claimed claim 1, wherein said appropriate action is a 
message sent to a network administrator. 

20. (Original) A method as claimed in claim 19, wherein said appropriate action is a 
message sent to an authorised person. 

21 . (Original) A method as claimed in claim 20, wherein said message is any one or 
more of the following message types: electronic mail; SMS text massaging; audio signal; 
telephone call; pagers; WAP appliances. 

22. (Previously Presented) A computer memory storing thereon an application 
program for controlling the execution of a processor to monitor events generated on at least 
one computer system, the computer program controlling the processor to: monitor a set of 
event data generated on at least one computer system; record said set of event data in a 
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dau.base. inter^ga.e s^d database .o .hereby selec. aler. even, da.a from sa,d se. oteven. 
dt— g .o a predefined se. of ™les; read said aler. even, da. and issue an appropn^e 
1 ,0 said g nera,ed even, on said eompu«r sys,en,. said aCion issued accordmg .o 
eTseofruies^a^^ 

:r„flsandbaseduponawe.gh,ingfac,orappiied,oreeordedHis,or.ca,ou,con,esfor 

™"T;tina,,Acon,pu,er™en,oryasc,ai™^ 
""°T;:;r":;u.er™e.noryase,ain,edi^ 

proJfiI*erJro,s,beprocessor,o issue sa.dae.ionresponse.o said a. ■eas.one 
compu.er sys.em .o preven. fcrther inieraCion a user of said eompu.er. 

:«ieon.pu.er.en.oryasc.ain.edine,ain..,w>.ere.nsaidse.ofeve„. 

.ranspor, layer; securi.y layer; opera.ing sys.em. 

9.8 (Oririnal) A compurer memory as claimed m claim 2 /, wn 
progrJiri.ui-.o„eormoreof.efollo„ingcus»merrela,ionsbipmanagemen,, 

en,erprise resource planning; cusromer biUing 

29 (Original) A compu,er memory as claimed m claim 27, wherem P 
3ys.em includes any one or more of .he following: da.abase app.ica.ion server; LAN, rou,er, 

inc,ude:ironeorLreof.hcfollo.ng.f— card-swipefaciliry access; c.^^^^^^^^^^ 

^'^"Ti'gTnal, A compu.er memory a. claimed in claim 22, wherein said comparer 
p.JXconL.he processor .opermi.anaudrorisednser.oin,erac,ively define 

""^to;in.)Acompu.er memory asc,aimedinclaim3,. Wherein said au*^^^ 

.erc.deLand.oramends.dse.ofru,esins,epusi„gaus.^ 

33. (Original) A computer memory as claimed in claim 32, wherem sai g 

interface is a web browser. 
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34. (Cancelled) 

35. (Original) A computer memory as claimed in claim 22, wherein one or more agent 
programs are provided on each computer system to monitor said set of event data. 

36. (Original) A computer memory as claimed in claim 22, wherein said event data is 
recorded in a relational database. 

37. (Original) A computer memory as claimed in claim 36, wherein said event data is 
assigned a unique log identifier in said database to identify the record of each event. 

38. (Original) A computer memory as claimed in claim 37, wherein said unique log 
identifier is used to correlated as a single event, a multiplicity of events generated on one or 
more computer systems. 

39. (Original) A computer memory as claimed in claim 22, wherein a report is 
generated to report said recorded set of event data. 

40. (Original) A computer memory as claimed claim 22, wherein said appropriate 
action is a message sent to a network administrator. 

41. (Original) A computer memory as claimed in claim 40, wherein said appropriate 
action is a message sent to an authorised person. 

42. (Original) A computer memory as claimed in claim 41, wherein said message is 
any one or more of the following message types: electronic mail; SMS text massaging; audio 
signal; telephone call; pagers; WAP appliances. 

43. (Previously Presented) A monitoring system for monitoring events generated on at 
least one computer system, said monitoring system comprising 

one ore more agent programs for monitoring a set of event data generated on said at 
least one computer system; 

a database for recording said set of event data in a database, said database adapted to 
be interrogated to thereby select alert event data from said set of event data 
according to a predefined set of rules; and 

action generation means for reading said alert event data and issuing an appropriate 
action to said generated event on said computer system, said action being 
issued according to said predefined set of rules and wherein the action is 
determined based upon said pre-defined set of rules and based upon a 
weighting factor applied to recorded historical outcomes for monitored events. 

44. (Original) A monitoring system as claimed in claim 43, wherein said action 
generation means issues said action response to said at least one computer system to prevent 
interaction of a user with said computer. 
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45. (Cancelled) 

46. (Original) A monitoring system as claimed in claim 43, wherein an authorised 
user is able to define said set of rules. 

47. - 55. (Cancelled) 
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